A phishing email is a message designed to trick you into clicking a bad link, opening a harmful file, entering a password, or sending money, usually by pretending to be someone you trust. The good news is that most of them share a handful of tells you can learn to spot in seconds.
Here is what to look for, whether it lands in a work inbox or a home one.
The common signs
- Urgency or fear. “Your account will be closed,” “payment failed,” “act now.” Pressure is meant to make you react before you think.
- A sender address that is slightly off. The name looks right, but the actual address is a jumble, or the domain is misspelled (micros0ft.com, paypaI.com).
- Links that do not match. Hover over a link (do not click) and check where it really goes. If the text and the address disagree, stop.
- Unexpected attachments. Especially invoices, receipts, or “documents” you were not expecting.
- Requests for passwords, codes, or payment. Real companies do not email asking for your password or a gift-card payment.
Here is what those tells look like in a real message:
Dear Customer, we noticed a sign-in from a new device.
Confirm my account3 now, or your access will be locked.
- 1Sender address is subtly wrong (…-verify.co, not your bank's real site)
- 2Urgency and fear, pushing you to act before you think
- 3A link that does not match the real company (hover to check)
- 4An unexpected attachment
What to do when an email looks off
Do not click or reply
Do not open attachments or tap links.
Verify through a channel you trust
Call the company using a number from their real website, not one in the email.
When in doubt, ask
Report it to whoever handles your IT at work, or ask someone you trust at home.
Delete it
Once you have confirmed it is not legitimate.
The single best habit is simple: slow down. Phishing works by rushing you. A ten-second pause to check the sender and the link stops the large majority of attacks.
Worried about phishing at your business or home? Get in touch for a plain-language look at your protection, or read more about managed security.
